Resolved an issue where automatic firmware updates were not installing

Resolved an issue in which adding ten or more traffic policy rules breaks rule ordering

Release 2019-02-04

Version 1.16.2

Improvements

Added functionality to the Connected Devices card that displays approximately when a device was last seen on a network

Added functionality that only triggers the device offline alert for service-linked DNA devices

Added functionality that consolidates custom DNS search domain settings for WAN ports & LTE into one setting in the new Global DNS card, simplifying the process for an operator

Added functionality that allows an operator to select Atlantic Standard Time (AST) as a time zone for a DNA

Added functionality that improves DNA alert processing time from 10 minutes to less than 1 minute

Bug fixes

Resolved an issue where a DNA could not check-in over LTE

Resolved an issue where triggered alerts displayed a timestamp five hours ahead of the local time of a DNA

Release 2019-01-11

Server release

Improvements

This release improves the readability and presentation of IDP logging.

While this functionality does not require a firmware upgrade, we've also added minor code enhancements to improve device functionality as part of 1.16.1. We recommend upgrading to the latest firmware release.

Operators can now allow or disallow subdomains as part of blacklisting or whitelisting in the Web Filters feature.

Bug Fixes

Resolved an issue where the DNA could not connect to legacy VPN sites

Resolved an issue where DNS traffic always redirected to the LAN gateway after disabling the Web Filters feature

Fixed an issue where the DNA falsely reported that a site-to-site VPN tunnel went down

Release 2018-10-02

Version 1.15.5

New Features

Alerts and Notifications: The DNA can now send out alerts to email recipients for events such as the appliance switching to LTE failover mode, unscheduled reboots, setting modifications, and more. For more information, read the DNA: Alerts Configuration article.

Advanced DHCP Options: Operators can set advanced DHCP options on a per LAN basis.

Improvements

The Web Filters feature now allows unclassified traffic by default.

Release 2018-09-12

Version 1.15.4

Bug Fixes

Resolved an issue where IPsec tunnel initiations would not establish on a responder DNA with client VPN enabled

Resolved an issue that prevented the login page from displaying after a device GUI session had expired

Fixed an issue that could cause LTE connectivity failures on some DNA-EA5-KZ1 units

Added functionality that will allow the DNA to auto-negotiate reconnection to a VPN peer device when failing over

Operators can now specify what LAN subnets are accessible in a site-to-site VPN setup

Bug Fixes

Resolved an issue where connecting to OpenVPN using the same credentials as another active session will cause that user to disconnect

Release 2018-05-17

Server release

New Features

Customizable Description Field: From the DNA Settings card, operators can label their DNA with a description separate from its hostname to assist with fleet management.

Bug Fixes

Resolved an issue where removing a spoke site in a multi-VPN setup would cause the hub DNA to lose all its configuration

Release 2018-05-02

Version 11.13.2

Improvements

For DNA-NA5-US units only, changed the default APN for the LTE connection to improve performance

Bug Fixes

Resolved an issue which caused an undesirable modification of SIP packets under certain circumstances

Release 2018-04-18

Version 1.13.0

New Features

WAN Load Balancing: Allows an operator to configure the DNA to use multiple WAN connections for increased throughput, per-WAN load percentages to allow optimal performance in deployments with asymmetric link capacity, and local subnets to prefer either the ISP 1 or ISP 2 interface.

Ethernet Settings: Adds a configuration card that allows an operator to adjust link speed and duplex settings for the appliance's physical ports.

Failover Policy Control: This feature allows an operator to interrupt existing sessions for LAN clients during transitions to and from 4G LTE failover, and to specify how the DNA disrupts the sessions.

Release 2018-03-14

Reorganized Device UI: The Datto Networking Appliance's user interface has been revamped to enhance navigation and promote ease of configuration. You can learn more about the new user experience by watching our UI tour video. For a full list of features, see our Datto Networking Appliance: Getting Started article.

Bug Fixes

Fixed an issue which could prevent the appliance's secondary WAN IP address from being displayed in the Network Overview panel

Resolved an issue that prevented appliances from saving WAN configurations where the SSID contained an emoji

Release 2018-03-08

Version 1.12.0.74147

Improvements

Operators are now able to configure WiFi frequencies on devices authorized for service in Australia and New Zealand

Bug Fixes

Resolved an issue where LTE did not work out-of-box for specific models, which required operators to register the DNA through a wired LAN connection as a workaround

Resolved an issue that could cause DHCP relay and static DHCP leases to interfere with the display of IP address for connected clients

Release 2018-02-27

Version 1.11.2.66162

New Features

Port Aggregation Status: Allows an operator to see the status of aggregated ports to verify that they are working as expected and to troubleshoot issues.

Fixed an issue that could prevent the description field on a configured WiFi card from being edited if an operator entered a blank value

Fixed an issue that prevented DHCP leases from being removed on the deletion of a VLAN

Fixed an issue that could cause an operator to be repeatedly prompted for credentials when connecting to an IKEv2 client VPN

Release 2018-02-13

Version 1.11

Improvements

The DNA now supports a subnet mask for /30, which is typically configured for LANs connecting to a point-to-point subnet

IPsec Profiles: Allows an operator to apply policy and encryption optimizations to a Site-to-Site VPN connection which are appropriate to the profile of the IPsec endpoint in the connecting environment

VPN Re-Key Improvements: The DNA will now create a new VPN tunnel before tearing down the existing one during the Automatic Tunnel Restart process, delivering a more seamless experience and ensuring connection continuity for devices connected through Site-to-Site VPN

Release 2018-01-24

Version 1.9.0.40368

New Features

Inter-Network Accessibility: Allows an operator to specify firewall rules between VLANs configured on the DNA, providing greater control over which VLANs can communicate with other VLANs

Static Host Mapping: Allows an operator to specify an IP address to resolve for a given hostname when queried by an internal client on the LAN

Port Forwarding: Allows an operator to specify a source IP when directing incoming network traffic to specific destinations within the LAN (firmware update not required)

Port Aggregation: Allows an operator to combine two or more NICs to act as a single logical link (LACP interface), enabling improved connection performance and redundancy for inter-network traffic passing through the DNA

Fixed an issue that could cause the DNA to show an update banner when an update was not available

Fixed an issue that could cause the Test Failover button to time out prematurely

Fixed an issue that could cause large subnets assigned to a LAN to report duplicate device connections

Fixed an issue that could cause IDP (Snort) to fill logs with ping reports for 8.8.8.8 and 8.8.8.4

Release 2018-01-10

Version 1.8.1.38278

New Features

Outbound NAT Support: Allows an operator to configure firewall rules which route traffic through alternate source IP addresses in the private subnets. This feature requires more than one static IP and permits you to specify which external IP address to use for a given host (one IP) or subnet

PPPoE Support: Allows an operator to configure either WAN connection to pass a username and password to an ISP connection, so that the connected router can authenticate to the modem

Release 2017-11-21

DHCP Relay: Allows an operator to configure a DHCP server external to the DNA for more centralized management of client IP addresses

Automatic VPN Tunnel Restart: lets operators specify a timeframe for re-keying site-to-site VPN tunnels after they are created

Automatic VPN Failback: When using a failover connection, site-to-site VPN will now automatically fail back to the primary WAN when it healths is restored

Bug Fixes

Fixed an issue that could cause the DNA to prompt for a subnet mask when configuring LANs incorrectly

Release 2017-11-09

Version 1.5.3.99

Improvements

Client VPN: Added enforcement of server certificate verification. The OpenVPN server must now present a compatible certificate before the client trusts the connection. After installing this firmware update, you will need to download new VPN Gateway Certificates and OpenVPN Config Files from the Client VPN card. Old certificates will no longer work

Bug Fixes

Fixed an issue that could cause the LTE connection to appear as unavailable when in actuality, the modem for LTE was becoming unresponsive. This fix will allow the DNA to recognize the modem state and re-establish communication

Fixed an issue that could prevent the DNA from going into LTE failover mode when an upstream device, such as an ISP modem, was disconnected

Release 2017-10-23

Version 1.4.4.93

Improvements

Updates to the Datto Networking Appliance, providing enhanced time zone support

Bug Fixes

Fixed an issue that could cause IPSec traffic to stop when specific interfaces were detached and reattached to the system by an operator

Release 2017-10-20

Server release

Terms of Service Updates

All device operators will be prompted to acknowledge the updated Terms of Service at the next device login. Once acknowledged, the Terms of Service prompt will not reappear

Release 2017-10-16

Version 1.4.0

Improvements

Updates to the Datto Networking Appliance providing additional modem and SIM support

Release 2017-10-09

Server release

New Features

Added functionality to allow the appliance to notify an operator of WAN / LAN conflicts from the Status page

Added a conditional DNS forwarding feature which allows the DNA to use a custom target IP address to resolve requests for specific URLs

Improvements

Added functionality to allow an operator to configure /16 subnets (subnets with a theoretical maximum of 65,536 addresses)

Added functionality to lock the UI if the DNA is configured as a spoke

Improved UI badging to more clearly indicate the role of each connection in a static configuration

Bug Fixes

Fixed an issue that could cause subdomain name length validation to be skipped on check-in

Fixed an issue that could cause multi-site-to-site migration to fail for very old siteVPN configurations

Fixed an issue that could prevent an operator from editing only the router address when configuring a subnet

Release 2017-08-07

Version 1.0.5.75.

Improvement:

Improves algorithm to determine LTE signal strength based on actual connectivity and ping.

Release 2017-08-03

Version 1.0.4.74

New Feature

Top Applications Reporting (Layer 7 DPI): Partners can view data usage on a per-application basis from the Network Usage card. Requires firmware version 1.0.4 or higher

Added update to OS that enables application data reporting through the UI

Improvement

Improved signal strength reporting through the UI

Release 2017-07-24

Server release

Features

1:Many NAT. Partners can now configure a 1:Many NAT environment through the GUI of the DNA appliance

Release 2017-07-12

Version 0.9.1.65

Bug Fixes

Fixed an issue with LTE failover which could cause the DNA to stop checking in

Fixed an issue which caused the Network Overview pane not to display OpenVPN connection details

Fixed an issue which could cause the DNA to display an incorrect network gateway in the WAN Details pane

Release 2017-07-10

Server release

Features

1:1 NAT. Partners can now configure a 1:1 NAT environment through the GUI of the DNA appliance

Release 2017-06-27

Server release

Bug Fixes

Fixed an issue that could cause the DNA to stop checking in after saving DHCP static reservations

Fixed an issue that could cause the client and site-to-site configurations to be superseded by port forwards

Release 2017-06-14

Server release

Features

OpenVPN Integration: Partners can now use OpenVPN to establish an SSL client VPN connection to the Datto Networking Appliance

Release 2017-06-13

Version 0.9.0.64

Features

DNA auto-update. DNA auto-update allows an operator to configure a schedule for the DNA to automatically update if and when there is a device update available, and if set parameters are met. The DNA does not send device updates without being manually initiated. The auto-update feature is off and not configured by default.

OpenVPN. This feature allows a user to configure an SSL Client VPN connection using the same client VPN feature currently in place. When enabled, the subnet is divided in two, allowing half of the subnet to use IPSec IKEv1 or IKEv2 client VPN connectivity, while allowing the other half of addresses to be configured for SSL (OpenVPN) client connectivity

Release 2017-06-12

Server release

Features

Site-to-Site VPN - Phase 3: When a DNA is configured for site-to-site VPN, the initiating DNA will tell the responder DNA to configure itself as the other VPN endpoint, performing all necessary handshakes automatically. This step eliminates additional configuration steps currently required for setting up site-to-site VPN

DNA Auto-Update: DNA auto-update allows an operator to configure update windows during which the DNA will automatically check for and apply software updates. The auto-update feature is off by default and must be manually enabled by the operator

Improvement

Hostname character limit: The UI now enforces 63 maximum characters per DNS name segment when configuring hostnames. This character limit is consistent with the RFC1123 standard

Fixed an issue where the DMZ stopped the client VPN from being able to connect

Fixed issue where creating a new LAN prevents site-to-site VPN from working on previous LANs

Release 2017-05-15

Server release

Feature

Configurable Channel Width: Allows operators to switch between the 20Mhz and 40Mhz WiFi channels to select the setting that best meets their needs

Improvement

Local DNS Resolution: This improvement ensures that clients remotely connecting over VPN will be able to resolve hostnames from a DNS server running on the DNA

Bug Fixes

Fixed a bug that could cause a rendering issue with the Domain Whitelist / Blacklist's Delete button

Fixed an issue where creating a new LAN could cause site-to-site VPN to not work on previously configured LANs

Release 2017-05-11

Server release

Bug Fix

Fixed a VPN issue causing statically-assigned WAN IP addresses to appear in the local and remote subnet data used to populate firewall rules and site VPN IPsec configurations

Release 2017-05-10

Version 0.8.0.54

Features

Client VPN status now displays in DNA management UI - Under Browse Networks, there is now a tab for VPN. This tab will provide detailed information on what is currently connected and the duration of that connection in real-time

Client VPN (Windows) no longer requires a third-party application - This is also known as IKEv2. Essentially the DNA facilitates a method to build a cert to deploy on clients running a Windows OS that once applied, eliminates the need for a third-party application

Bug fixes

Fixed an issue where some websites had been blocked, even after turning off web filtering. Note that you may still need to clear the cache on the client's OS and Web Browser. The DNA does not currently have access to this

Fixed an issue where the device stopped collecting bandwidth data after a long period since a reboot

Fixed the absence of "DNA booted" message when DNA boots in System Events

Fixed an issue where enabling Site to Site VPN broke the UI

Release 2017-05-04

Server release

Features

Client VPN Status: Adds a GUI element to provide a real-time view of all devices and clients connected to a DNA

Site-to-Site VPN - Phase 2: Adds one-click configuration when setting up a site-to-site VPN connection, eliminating manual steps. Also adds auto-discovery of WAN IP and LAN IP ranges, and auto-generates and assigns a new Pre-Shared Key (PSK) to the DNA

IKEv2 for Client VPN: Adds support for native VPN connections to remove the dependency on third-party VPN applications to connect to a DNA's LAN

Fixed bug where LAN shows WAN/LAN conflict when newly created - Previously when creating a new LAN in the UI it showed the message that a WAN/LAN subnet conflict was resolved, even though that wasn't the case since the LAN didn't exist yet

Improved "Site Blocked" page served up when web filter rule is triggered - Language referencing the DNA has been removed, and general syntax has been updated

Implementation of Dynamic DNS (DDNS) - The DNA now provides a persistent addressing method for the DNA so that WAN IP address changes will not impact services that require a consistent inbound address

DNA Now supports system logs in Network Overview - The DNA now collects and reports system logs for the following events:

Added whitelist and blacklist for web filters - The DNA Web Filtering feature now supports adding whitelists and blacklists for specific sites to work in combination with existing web filter categories

Site to Site VPN support - The DNA now supports IPSec Site to Site VPN between another DNA

IP Address Reservations (DHCP Reservations): Allows the reservation of a static IP, within a subnet range of a VLAN, to be statically assigned to a specific device by MAC Address, on a per-VLAN basis

Remote Power-Cycle DNA: Adds a UI element to allow ‘soft’ reboot functionality of the DNA through the DNA management interface

Dynamic DNS: Provides a persistent addressing method for a DNA so that WAN IP address changes will not impact services that require a consistent inbound address, e.g., for local exchange server, client VPN server. The DDNS name is factory configured and is not user-configurable

Web Filtering Whitelisting / Blacklisting: In addition to web filter categories, the DNA now offers the option of adding sites to either whitelists or blacklists

System Logging: Adds a UI element to report DNA system events; this is a view-only system log which displays historical changes on the DNA

Bug Fixes

Fixed an issue that could cause a false WAN/LAN conflict message on initial LAN creation.

Adds firewall rules to allow traffic between VPN endpoints across the tunnel, ensuring that a client system behind a DNA can communicate with a client system behind another DNA, even with the firewall running. It also ensures that client systems can communicate across a tunnel, yet when a tunnel drops and is restarted

Fixes an issue that could cause a factory reset not correctly to refresh the UI

Release 2017-03-09

Server release

Bug Fix

Fixes an issue that could cause some DNAs to be unable to communicate across the Client VPN tunnel

Release 2017-03-01

Server release

Bug Fixes

Fixed an issue that could cause a static WAN IP to not display on the WAN Card after being configured

Fixes an issue that could cause network interruption when changing a WAN description

Release 2017-02-28

Release 0.5.4.45

This release includes client-side updates that require new software downloads. You should upgrade your device to ensure the best results

Features

Updates to heartbeat: Heartbeat controls the DNA's check-ins with its webserver to orchestrate communications. This update makes the service more robust

Hardening the LTE modem manager: this hardening ensures that your DNA will get a single IP address from Verizon without rebooting the modem or DNA